Published: 09/08/26
Today’s pattern is control-plane comedy with a body count: remote-access gateways, artifact registries, print servers, and the NetScaler that forgot to check the badge—four places teams trust because “that’s infrastructure,” right until infrastructure starts issuing its own sessions.
Lead Story
### SonicWall SMA1000 Turns Work Place Into a Path to Root
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
SonicWall disclosed CVE-2026-83548 (pre-auth SSRF, CVSS 10.0) and CVE-2026-83549 (AMC command injection, CVSS 7.8) on September 1. Chained, they yield unauthenticated RCE on SMA1000 models 6210, 7210, and 8200v. Fixes: 12.4.3-03526 and 12.5.0-02952. CISA added both to KEV on September 2. Exploitation was observed before the advisory; patching alone is not a clean bill of health.
Why it matters: The remote-access appliance answers for your workforce. Re-image when integrity is uncertain, rotate passwords and TOTP, and treat pre-disclosure exposure as an incident window.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
### JFrog Artifactory Phantom Join Key Mints Admin Tokens
CVE-2026-82329 (CVSS 9.8) lets attackers forge join JWTs against a deterministic empty join key on default self-hosted Artifactory, then exchange into platform admin. Fastly saw attempts peak near 406,000 on September 2. Fixed builds include 7.146.38 and 7.161.20 (plus matching fixes on older trains). A patch does not revoke tokens already minted.
Why it matters: Registry admin is supply-chain admin. Hunt POST /access/api/v1/registry/join with HTTP 201, rotate the join key, and revoke tokens since August 28.
Read more on CyberExperts: Read more
### PaperCut NG/MF Chain Needs Emergency Patch Release 2
CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE on PaperCut Application Server. Exploitation preceded disclosure; Release 2 hardens beyond the first emergency fix for v24/v25/v26. Older majors should upgrade.
Why it matters: Print consoles still touch directories and site-wide queues. Confirm Release 2, restrict admin reachability, and hunt the PaperCut host like it might already have company.
Read more on CyberExperts: Read more
### Citrix NetScaler CVE-2026-19490: PoC Yesterday, Probes Today
CVE-2026-19490 (CVSS 9.3) is an authentication bypass on NetScaler ADC/Gateway when configured as Gateway or AAA. Citrix patched August 19; a public PoC on September 2 was followed by live exploitation attempts within about a day. Fixed builds include 14.1-73.32 and 13.1-63.21 (plus matching FIPS/NDcPP). No workaround. Newer trains often need SAML configured; older builds can be exposed with Gateway/AAA alone.
Why it matters: Perimeter auth brokers do not get a grace period. Patch the fixed builds, confirm your config is in scope, and hunt unexpected sessions from the PoC window forward.
Read more on CyberExperts: Read the analysis
Go Deeper
Editorial Promise
CyberExperts should help you turn headlines into decisions. The value is in pulling the operational facts forward before the day turns them into background noise.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Get the Brief
Free. Weekday mornings. Unsubscribe anytime. Built from 100+ trusted cybersecurity sources.
#### George Bailey
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.